YFarmX logoYFarmX

Tools AI Risk Radar ai-incident-0076

Incident record

Goose recipe security scan misses executable extension and retry fields

Severity
High
Status
Proof-of-concept
Type
Agent Hijack
Target
goose recipes
Actor
researcher
CVE
CVE-2026-85623

What happened

The CVE published on 4 September records command execution through shared recipes, whose stdio extension commands and retry checks bypass the recipe security scan. The record lists versions through 1.49.0 as affected and assigns CVSS 3.1 8.8. The researcher’s public issue dates to July; this entry dates the CVE publication. Review executable fields before running a shared recipe. The cited issue remains open at the 10 September check.

Sources

One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026